Microsoft Sentinel, Azure Policy

Praveen Ayyasamy 40 Reputation points
2024-07-25T05:11:00.2766667+00:00

I am having a greater number of Azure Databricks, I need to integrate the audit logs of Data Bricks to Sentinel. Currently there is no in-built Data Connector. Manually going to each Data Bricks and adding Diagnostic settings is not possible. There is an Azure Policy for Data Bricks, but there is no option to select only the audit logs. Please suggest some solution for this.

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
867 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,122 questions
0 comments No comments
{count} votes

Accepted answer
  1. Prashant Kumar 775 Reputation points Microsoft Employee
    2024-07-30T13:12:30.0966667+00:00

    Hi Praveen,

    Azure Built-in Policies do provide option to select the category group - audit or alllogs for configuring Diagnostics settings for Azure Databricks Services through policy.

    While assigning the policy, you can select either of the option - audit or alllogs.

    User's image

    Built-in Policies:

    User's image

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Stanislav Zhelyazkov 23,501 Reputation points MVP
    2024-07-25T07:12:30.23+00:00

    Hi,

    Make a copy of the built-in policy and modify it so it applies only the logs that you want. After that apply it and remediate if necessary.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.